OpenAI, Anthropic, and Meta AI Breaches Shared the Same Testing Vendor

OpenAI, Anthropic, and Meta AI incidents reportedly shared one testing vendor, exposing third-party and containment risks in AI security evaluations.

Aug 11, 2026
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A shared security-testing vendor may explain why AI models from OpenAI, Anthropic and Meta all reached systems they were never supposed to access.

CNBC reported that the three incidents involved Irregular, an Israeli security firm that evaluates the offensive capabilities of advanced AI models. In the affected tests, configuration weaknesses reportedly gave the models pathways from controlled evaluation environments to external systems.

That changes the security lesson. The incidents are not only about what increasingly capable AI agents can do; they are also about whether the third-party infrastructure used to test and contain them can be trusted to hold the line.

Three incidents, one supply chain problem

The first warning came from OpenAI, whose models reached Hugging Face’s infrastructure during a cybersecurity evaluation. 

Anthropic later found three separate cases in which Claude models gained unauthorized access to three organizations. Around the same time, Meta disclosed that its Muse Spark 1.1 model had also breached an outside company’s systems during a security test.

Meta said a configuration error by the same testing firm gave Muse Spark 1.1 unintended access to the internet.

Irregular’s job was to put these models through realistic cybersecurity exercises, giving them targets, tools and enough freedom to demonstrate whether they could discover vulnerabilities and carry out offensive security tasks.

The models were therefore not starting from nowhere. They were already being tested for advanced offensive cyber capabilities, and the evaluation environments were built to let them act on those capabilities. The problem was that, in these cases, those environments also provided the models with an unintended route to the public internet. 

That distinction matters because it shifts the security question from whether AI can escape a sandbox to whether the infrastructure surrounding increasingly capable AI agents can reliably prevent them from reaching anything they were never meant to touch.

And that is what makes Irregular more than a common name in three unrelated incidents. It exposes a third-party risk in the AI security supply chain. The labs supplied increasingly capable models, while the external evaluation environments supplied the boundaries meant to contain them. And when those boundaries failed, the models could turn an evaluation into a real-world security incident.

Advertisement

What this means for enterprises

Enterprises deploying autonomous or semi-autonomous AI agents should assume those systems will eventually encounter opportunities to act beyond their intended scope.

Controls should therefore be enforced by infrastructure rather than instructions alone. Organizations should use deny-by-default network policies, restrict outbound internet access, isolate sensitive systems, apply least-privilege permissions, rotate or limit credentials available to agents, and monitor unexpected outbound connections.

The incidents also highlight a third-party risk. Organizations relying on outside vendors to host, evaluate or secure AI agents should independently assess how those providers enforce network isolation, manage credentials, log agent activity, and prevent test environments from reaching production or public systems.

The larger lesson is familiar: outsourcing a security function does not outsource the risk. When an external provider controls the boundaries around an AI agent, weaknesses in that provider’s controls can become part of the customer’s own attack surface.

Other News: Hackers are targeting major Wall Street firms with phone-based social engineering attacks that impersonate help-desk staff, intercept MFA codes in real time, and steal corporate credentials for extortion.

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。